CVE-2026-60002 - High Severity Vulnerability
Vulnerable Library - freebsd-srcrelease/15.0.0-p7
The FreeBSD src tree publish-only repository. Experimenting with 'simple' pull requests....
Library home page: https://github.com/freebsd/freebsd-src.git
Found in base branch: master
Vulnerable Source Files (1)
Vulnerability Details
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Publish Date: 2026-07-08
URL: CVE-2026-60002
CVSS 3 Score Details (7.7)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-07-08
Fix Resolution: https://github.com/openssh/openssh-portable.git - V_10_4_P1
Step up your Open Source Security Game with Mend here
CVE-2026-60002 - High Severity Vulnerability
The FreeBSD src tree publish-only repository. Experimenting with 'simple' pull requests....
Library home page: https://github.com/freebsd/freebsd-src.git
Found in base branch: master
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Publish Date: 2026-07-08
URL: CVE-2026-60002
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Type: Upgrade version
Release Date: 2026-07-08
Fix Resolution: https://github.com/openssh/openssh-portable.git - V_10_4_P1
Step up your Open Source Security Game with Mend here